CVE-2014-1421
published 2014-11-25CVE-2014-1421: mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.51%
40.5th percentile
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-284v-wmgp-rgxg: mountall 1
ghsa_unreviewed·2022-05-17
CVE-2014-1421 [HIGH] GHSA-284v-wmgp-rgxg: mountall 1
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
Ubuntu
mountall vulnerability
vendor_ubuntu·2014-11-18
CVE-2014-1421 mountall vulnerability
Title: mountall vulnerability
Summary: mountall could mount certain filesystems with the wrong permissions.
Saurav Sengupta discovered that mountall incorrectly handled umask when
calling the mount utility, resulting in certain filesystems possibly being
mounted with incorrect permissions.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-11-25
Published